Location
London
Hours
Follow-the-sun shift rotation: 1200hrs - 0000hrs (midday to midnight) London Time, 4 days on, 4 days off rotation
Salary
Negotiable
About the Role
The London Stock Exchange Group (LSEG) is seeking an experienced, dedicated, and driven Attack Monitoring Analyst to join the Global Security Operations Centre (GSOC) team. LSEG Security Operations is a central function that employs people, processes, and technology to continuously monitor and respond to cyber security incidents. This role is responsible for identifying and responding to cyber security incidents and enhancing the defensive capabilities of the GSOC.
The ideal candidate will have a strong technical background with a firm understanding of modern attack techniques and the typical lifecycle of cyber attacks. You will triage security events, respond methodically to incidents using playbooks, operate SIEM tools such as Splunk, QRadar, or LogRhythm, and develop monitoring dashboards and run books. Staying current with vulnerabilities, attacks, and countermeasures is essential. You will also research and collect threat intelligence to improve the SOC’s detection capabilities and remediate cyber events generated through monitoring technologies.
Join a dynamic organisation of 25,000 people across 65 countries, where innovation, quality, and continuous improvement are valued. LSEG is committed to diversity, inclusion, and sustainability, offering a collaborative and creative culture with tailored benefits including healthcare, retirement planning, paid volunteering days, and wellbeing initiatives.
Experience
- Operating or administrating SIEM platforms such as Splunk, QRadar, or LogRhythm
- Solid understanding of networks including the TCP/IP stack, typical organisational architectures, and common protocols abused by malware
- Security event analysis, triage, incident handling, and root-cause identification
- Knowledge of attacker tools, techniques, and procedures, ideally from direct experience
- Cyber security knowledge gained academically or within corporate environments
- Ability to work calmly in a fast-paced and demanding environment
- Strong verbal and written communication and collaboration skills
- Security industry certifications such as OSCP, GIAC, CCNA
- Certifications demonstrating SIEM operational competence
- Proficiency in one or more programming languages (e.g. Python, PowerShell, Java, C#)
About you
You are technically skilled, analytical, and proactive with a passion for cyber security. You thrive in a collaborative environment and are committed to continuous learning and improvement. Your communication skills enable you to work effectively across teams and convey complex information clearly.
Qualifications
Relevant security industry certifications and technical accreditations are highly desirable. Demonstrated competence with SIEM tools and programming languages will be advantageous.
London Stock Exchange Group











